Appearance
Set Up Microsoft SSO
Microsoft SSO lets users sign in to their Wombat account using a Microsoft account. Wombat uses the Microsoft identity provider and requests the delegated User.Read permission to identify the signed-in user and read their basic profile.
Wombat does not import Microsoft groups, roles, or permissions. A user must still be created in Wombat and assigned the appropriate Wombat role and access.
Before You Start
Identify two administrators. They may be the same person:
- A Wombat administrator who can create users and assign Wombat permissions.
- A Microsoft Entra administrator who can review or approve the Wombat application if your organization's consent policy requires it.
Before the first sign-in:
- Create the administrator in Wombat using the same primary email address they use for their Microsoft account.
- Make sure the Wombat user is active and has the required administrator permissions.
- Confirm that the Microsoft account is active and permitted to use third-party enterprise applications.
- Ask your Microsoft Entra administrator whether user consent is allowed. If it is not, plan for the administrator to approve the application during the first sign-in attempt.
Email addresses must match
Use the email returned by the Microsoft account, not an unverified alias or a different Microsoft account. A mismatch can create an account-linking error or result in a successful Microsoft sign-in with no Wombat access.
First Administrator Sign-In
The first Wombat administrator should complete the following steps before Microsoft SSO is announced to other users:
- Open the Wombat sign-in page in a private browser window. This avoids accidentally selecting an existing personal Microsoft session.
- Select Microsoft.
- Choose the expected account. Wombat asks Microsoft to show the account picker, so seeing this choice is normal.
- Complete your organization's Microsoft sign-in requirements, such as multifactor authentication or Conditional Access.
- Review the requested permission and accept it if your organization allows user consent.
- If Microsoft shows Need admin approval or Approval required, stop and have a Microsoft Entra administrator approve the request. Retry the sign-in after approval.
- Allow Wombat to return to the sign-in page and finish linking the account. The first sign-in may show a Linking your account message and may redirect through Microsoft a second time.
- Confirm that Wombat opens the expected organization, tenant, division, or site and that the administrator can access the required administration pages.
When Wombat uses its server-side account-linking flow, it queues a New Login Method email. Links completed through Microsoft's standard provider-linking flow may not generate this email. Future sign-ins use the same Microsoft button and normally do not repeat the linking step.
Microsoft Entra Consent
The User.Read delegated permission does not normally require tenant-wide administrator consent. Administrator approval is not required when your organization's policy allows the user to consent to Wombat, or when individual or tenant-wide consent was already granted. However, your organization's application consent policy may prevent users from approving new applications.
If administrator approval is required, the Entra administrator should:
- Review the application name, publisher, and requested permissions shown by Microsoft.
- Approve the pending request through the organization's normal application approval process, or grant tenant-wide consent from Microsoft Entra admin center > Entra ID > Enterprise apps > All applications > [Wombat application] > Security > Permissions.
- If the enterprise application requires user assignment, assign the pilot administrator and the users or groups that need Wombat access.
- Ask the pilot administrator to sign in again from a private browser window.
See Microsoft's documentation for user and administrator consent and granting tenant-wide administrator consent.
Roll Out Microsoft SSO
After the administrator test succeeds:
- Create or import each user in Wombat before asking them to sign in.
- Use the same primary email address stored in Microsoft Entra ID.
- Assign each user a Wombat role, permissions, and the correct organization, tenant, division, or site access.
- Ask a small pilot group to sign in with Microsoft and confirm their landing location and access.
- Send the sign-in instructions to the remaining users.
For a new Wombat user who has never signed in, the first Microsoft sign-in normally links automatically. The user's Microsoft password and multifactor authentication settings remain managed by Microsoft and are not stored in Wombat.
Existing Wombat Accounts
An existing user may already have a password, Google, or Microsoft login method linked to the same email address. Wombat will not silently replace an established login method.
Depending on the account state, the user may be asked to:
- Sign in with the existing method so Wombat can verify ownership and link Microsoft.
- Complete the Linking your account flow and return to Microsoft.
- Contact Wombat Support so a temporary Microsoft-linking window can be opened.
A support-authorized linking window lasts 24 hours. The user must use the emailed sign-in link and complete the Microsoft sign-in before it expires. Opening a linking window authorizes an additional login method; it does not remove the user's existing method.
What Users Should Expect
- Selecting Microsoft redirects the browser to Microsoft's sign-in page and then back to Wombat.
- Microsoft may require multifactor authentication, device compliance, location checks, or other Conditional Access controls.
- The Microsoft account picker may appear even when the user is already signed in.
- A consent screen may appear on the first sign-in unless an administrator has already granted consent.
- New accounts may briefly show an account-linking dialog and perform a second redirect.
- Users linked through Wombat's server-side linking flow receive an email when Microsoft is added as a login method. Other successful linking paths may not send this email.
- Wombat access is controlled by the user's Wombat status and permissions, not by Microsoft group membership.
Troubleshooting
| Symptom | Likely cause | What to do |
|---|---|---|
| Microsoft shows Need admin approval or Approval required | The organization's user-consent policy blocks the application | Submit the approval request or have a Microsoft Entra administrator review and grant consent, then retry |
| Microsoft says the user is not assigned to the application | The enterprise application requires user assignment | Assign the user or an appropriate group to the Wombat enterprise application in Microsoft Entra ID |
An AADSTS50020 or wrong-tenant message appears | The browser selected a personal account, guest identity, or account from another Microsoft tenant | Sign out of Microsoft and retry in a private window with the expected work or school account |
| Wombat says the account already has another login provider | The email is already linked to a previously used password, Google, or Microsoft identity | Follow the prompt to sign in with the existing method; if that is not possible, contact Wombat Support for a 24-hour Microsoft-linking window |
| The linking email no longer works | The temporary linking window expired | Ask Wombat Support to issue a new link and complete it within 24 hours |
| Microsoft sign-in succeeds, but Wombat shows no access or the wrong location | The Wombat user was not provisioned, is inactive, has different email data, lacks permissions, or has another default location | Verify the user's email, active status, Wombat permissions, and organization or site assignments |
| The first sign-in loops or remains on loading | The redirect state or browser site data is stale, or privacy software blocked part of the redirect | Close extra Wombat tabs, retry in a private window, allow cookies and redirects for Wombat and Microsoft, and temporarily disable blocking extensions for the sign-in |
| Microsoft rejects the sign-in after the Wombat redirect | Conditional Access, multifactor authentication, device compliance, or sign-in-risk policy blocked the request | Have the Microsoft Entra administrator review the user's Microsoft sign-in logs and policy result |
| Wombat reports that the provider did not verify the email or could not link the account | Microsoft returned an email or identity that does not safely match the existing Wombat account | Confirm the user's primary Microsoft email and Wombat email match, then contact Wombat Support rather than creating a duplicate user |
| The New Login Method email does not arrive | The account used Microsoft's standard provider-linking flow, or mail was filtered or delayed | If Microsoft sign-in succeeds, linking is complete. Otherwise, check junk and quarantine folders before contacting Wombat Support |
Information to Collect for Support
If the issue continues, send Wombat Support:
- The user's Wombat email address.
- The Microsoft email address they selected.
- The approximate time of the failed attempt and the user's time zone.
- A screenshot or the complete Microsoft
AADSTSerror code, without passwords or authentication codes. - Whether the account can still sign in using password or Google.
- Whether Microsoft Entra consent and user assignment have been completed.
Do not send passwords, multifactor authentication codes, access tokens, or ID tokens.